/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How the Conti ransomware group, whose attacks crippled Costa Rica's digital infrastructure for months, fell apart after it was betrayed by one of its insiders

Jorge Mora, Costa Rica's digital governance chief, received a message in April from one of his officials: “We couldn't contain it and they've encrypted the servers. Tweets: @obsoletedogma , @peterwhiteneck , and @m_miho_jpn Tweets: Matt O'Brien / @obsoletedogma : One of the only things crypto actually does do is make it easier to carry out ransomware attacks—like the one that has crippled Costa Rica's IT infrastructure & hurt a lot of vulnerable people https://www.ft.com/... https://twitter.com/... Peter Whiteneck / @peterwhiteneck : Great read on how 27 government ministries in Costa Rica were successfully attacked by #Conti—a notorious ransomware group that fell apart following the invasion of 🇺🇦 due to differing allegiances—and left Costa Rica without the keys to reclaim its data https://www.ft.com/... @m_miho_jpn : The stand-off caused by the Conti ransomware attack left parts of Costa Rica's digital infrastructure crippled for months, paralysing online tax collection, disrupting public healthcare and the pay of some public sector workers. https://www.ft.com/...

Financial Times

Context & Ripple Effects

Conti spent spring 2022 running a pressure campaign against a sovereign state: after encrypting servers across 27 Costa Rican government ministries, it published 672GB of agency data, prompting the president to declare a state of emergency, then doubled its ransom to $20M while urging citizens to push their own government to pay. The FT's account closes that arc by explaining how the group itself came apart — betrayed from within, and already fractured by differing allegiances after Russia's invasion of Ukraine.

The collapse had been visible in pieces before this reporting: AdvIntel tracked that Conti took its infrastructure offline in May, with leaders partnering with smaller ransomware groups instead. The insider-betrayal story explains why the brand died even as its operators kept working.

First-order effects

  • Costa Rica's digital governance operation under Jorge Mora is left rebuilding encrypted ministry systems — tax collection and healthcare services were paralysed for months — with no ransom paid to Conti.
  • Conti ceases to exist as a coherent group: its infrastructure goes dark and its leadership scatters into partnerships with smaller ransomware crews.

Second-order effects

  • Conti's operators resurfacing inside other groups means the techniques honed against Costa Rica — data publication plus citizen-pressure tactics — migrate to whichever brand absorbs them, making attribution harder for defenders.
  • Governments watching Costa Rica refuse a doubled $20M demand get a live test case of non-payment under maximal coercion, including Conti's stated aim to overthrow the government.

Third-order effects

  • Ransomware is consolidating around fluid operator networks rather than durable brands: when a flagship like Conti can be dismantled by one insider and a geopolitical split, the capability persists while the name does not.
  • Attacks on national infrastructure are pushing states to treat ransomware as a national-security problem rather than a corporate IT cost — Costa Rica's state of emergency was the template, and Ireland's earlier Conti hit on its public health system showed the same playbook aimed at another government.

The trend: Ransomware groups are shifting from stable branded syndicates to re-forming operator networks whose survival no longer depends on any single brand surviving.

Discussion

  • @peterwhiteneck Peter Whiteneck on x
    Great read on how 27 government ministries in Costa Rica were successfully attacked by #Conti—a notorious ransomware group that fell apart following the invasion of 🇺🇦 due to differing allegiances—and left Costa Rica without the keys to reclaim its data https://www.ft.com/...
  • @m_miho_jpn @m_miho_jpn on x
    The stand-off caused by the Conti ransomware attack left parts of Costa Rica's digital infrastructure crippled for months, paralysing online tax collection, disrupting public healthcare and the pay of some public sector workers. https://www.ft.com/...